# Filebeat decode\_json\_fields failed

**URL:** https://discuss.elastic.co/t/filebeat-decode-json-fields-failed/291019
**Category:** Beats
**Tags:** filebeat
**Created:** [December 6, 2021, 8:25am UTC](https://discuss.elastic.co/t/filebeat-decode-json-fields-failed/291019 "2021-12-06T08:25:25Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![haoma2514](https://avatars.discourse-cdn.com/v4/letter/h/4af34b/32.png) [@haoma2514](https://discuss.elastic.co/u/haoma2514)
#### Post date: [December 6, 2021, 8:25am UTC](https://discuss.elastic.co/t/filebeat-decode-json-fields-failed/291019/1 "2021-12-06T08:25:25Z")

</div>

![截图_20211206162157](https://us1.discourse-cdn.com/elastic/original/3X/5/e/5ea74f412be752d3c40eac6c47c502c7fa965e6c.png)

If the length of the message above is greater than 1116, it will be lost after formatting! When using filebeat decode\_json\_fields to parse json object, if the field content of json key is too long, it will be discarded directly. Which attribute should be set?

Message field is a string type. No matter any character entered, if it exceeds a certain length, it will be lost after formatted and stored in es.

The following is the content of my profile

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths: 
    - /opt/site/TestAPI/collectlog/current.log
  multiline.pattern: ^{ "time"
  multiline.negate: true
  multiline.match: after
fields_under_root: true
fields: {server: "VMTest" }

# ======================= Elasticsearch template setting =======================

setup.template.settings:
  index.number_of_shards: 1
  index.number_of_replicas: 0
setup.template.type: index
setup.template.enabled: true
setup.template.overwrite: true
setup.template.fields: "yy_server_log_fields.yml"
setup.template.name: "yy_server_log_index_template"
setup.template.pattern: "yy_server_log*"
setup.ilm.enabled: false 
 
output.elasticsearch:  
  hosts: ["localhost:9200"]
  index: "yy_server_log_%{+yyyy.MM.dd}"
  #protocol: "https" 
  #api_key: "id:api_key"
  username: "elastic"
  password: "some_password"
 

# ================================= Processors =================================
processors:
  - decode_json_fields:
      fields: ["message"]
      process_array: false
      max_depth: 1
      target: "yylog"
      overwrite_keys: false
      add_error_key: true
  - drop_fields:
      fields: ["log","host","input","ecs","agent"] 
      ignore_missing: true 

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 3, 2022, 10:25am UTC](https://discuss.elastic.co/t/filebeat-decode-json-fields-failed/291019/2 "2022-01-03T10:25:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
